My college-provided Microsoft 365 account may have been compromised. I began receiving more than 1,600 delivery-failure messages addressed to different, random-looking recipients, mostly appearing between August 12 and 17. I also received a message claiming that my college address had appeared in Telegram channels containing stolen data. I initially assumed it was a scam, but I later found indications that my credentials may actually have been exposed.
I have started securing the account from a clean device, but I am unsure whether the bounce-backs mean messages were sent through my mailbox or whether someone simply spoofed my address and the failures are backscatter. I am especially concerned that an infostealer or Trojan on my PC may have stolen passwords, browser cookies, or session tokens.
What should I do next on the computer side? I am considering Microsoft Defender Offline, full malware scans, checking for infostealers and persistence, revoking credentials and tokens, and possibly wiping and reinstalling Windows. I do not want to rely only on a clean scan result if the machine may still be compromised.
What logs or other evidence should I preserve before cleaning or reinstalling the computer, and how can I determine whether the account activity came from the mailbox itself? I will only share redacted evidence and will not post passwords, cookies, tokens, recovery codes, or other sensitive information.
4 Answers
Before wiping the machine, collect only evidence that cannot expose secrets: Defender and Windows event logs, suspicious file paths and timestamps, browser extension lists, installed programs, scheduled tasks, startup entries, and redacted screenshots. Do not upload raw browser profiles, cookies, token files, memory dumps, or password stores. If the account is managed by the college, let its IT team guide the investigation because preserving logs and reporting a possible institutional breach may matter more than running repeated local scans.
The bounce-backs alone do not prove that your mailbox was hacked. Attackers can forge your address in the From field, causing delivery failures to come back to you. Evidence such as unfamiliar successful sign-ins, sent messages in the mailbox, new forwarding rules, changed recovery details, or suspicious application access is much stronger. Your college administrators should be able to distinguish real account activity from simple spoofing in the service logs.
If you believe the Windows installation was exposed to an infostealer, the most reliable cleanup is to back up only personal documents, erase the system drive, and perform a fresh installation from official Microsoft media. Keep the computer offline until that is done if practical. Do not back up executables, cracked software, browser profiles, extensions, or copied password databases. After reinstalling, fully patch Windows, enable security protections, and change passwords again from the clean system.
Contact your college IT or security team immediately. They can check Microsoft 365 sign-in logs, mailbox audit logs, forwarding rules, inbox rules, sent items, OAuth app consents, and whether messages were actually submitted from your account. Change the password from a known-clean device, enable multifactor authentication, revoke active sessions and refresh tokens, remove unfamiliar apps or rules, and secure any other accounts that reused the password. Preserve the suspicious emails and their full headers, timestamps, sign-in alerts, and relevant screenshots without exposing secrets.

Exactly—if the messages are not in Sent Items and the audit logs show no outbound activity, it may only be backscatter. Still treat any confirmed credential exposure seriously and rotate the credentials and sessions.